StackRadar

CVE-2022-48285

High

Advisory

Published 29 Jan 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

JSZip contains Path Traversal via loadAsync

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
jszipnpm2.4.0, 2.5.0, 3.4.0, 3.6.0+2 more3.8.014
OSV records
GHSA-36fh-84j7-cv5h

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
jszip@3.7.1
3.8.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
jszip@3.7.1
3.8.0

Open the chart page →

18,517
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
jszip@3.7.0
3.8.0

Open the chart page →

24,488
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
jszip@3.4.0
3.8.0

Open the chart page →

5,941
cryptpadgeek-cookbookVerified publisher0.4.21 of 1See more

cryptpad geek-cookbook 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
jszip@3.7.1
3.8.0

Open the chart page →

974
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
jszip@3.4.0
3.8.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
jszip@3.4.0
3.8.0
governify/registry:v3.4.0d3f37f4f8168
jszip@3.4.0
3.8.0

Open the chart page →

24,319
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
jszip@2.5.0
3.8.0

Open the chart page →

57,669
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
jszip@3.7.1
3.8.0

Open the chart page →

4,230
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jszip@2.5.0
3.8.0

Open the chart page →

14,809
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jszip@2.5.0
3.8.0

Open the chart page →

1,948
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
jszip@3.6.0
3.8.0

Open the chart page →

5,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
jszip@3.7.1
3.8.0

Open the chart page →

3,638
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
jszip@2.4.0
3.8.0

Open the chart page →

20,270
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-48285.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
jszip@3.7.1
3.8.0

Open the chart page →

3,129

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
governify/registry:v3.4.0d3f37f4f8168
jszip@3.4.0
3.8.0
2
mojaloop/reporting:v12.1.0d480a62103d6
jszip@2.5.0
3.8.0
2
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
jszip@3.7.0
3.8.0
1
enketo/enketo-express:3.0.4dcad9c2273f6
jszip@3.7.1
3.8.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
jszip@3.4.0
3.8.0
1
gristlabs/grist:0.7.96e71b1914a7e
jszip@3.6.0
3.8.0
1
ibmcom/microclimate-theia:lateste17bdccc5030
jszip@2.5.0
3.8.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
jszip@3.7.1
3.8.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
jszip@3.7.1
3.8.0
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
jszip@3.7.1
3.8.0
1
samajh/alprfrontend:latest05ef4fddbb75
jszip@2.4.0
3.8.0
1
stanfordoval/almond-server:latest1a63cdccedaf
jszip@3.7.1
3.8.0
1
wekanteam/wekan:v4.2268a51f0327df
jszip@3.4.0
3.8.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
jszip@3.7.1
3.8.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.